On Jun 14, 2007, Robin Getz <rgetz@blackfin.uclinux.org> wrote:
I actually left out the most obvious one: store the program in ROM.
Is that not practical?
You're claiming that adding hardware locks and chains and bolts,
implemented with help from the loader software, is simpler than just
using ROM?
Well, then, ok: do all that loader and hardware signature-checking
dancing, sign the image, store it in the machine, and throw the
signing key away. This should be good for the highly-regulated areas
you're talking about. And then, since you can no longer modify the
program, you don't have to let the user do that any more. Problem
solved.
--
Alexandre Oliva http://www.lsd.ic.unicamp.br/~oliva/
FSF Latin America Board Member http://www.fsfla.org/
Red Hat Compiler Engineer aoliva@{redhat.com, gcc.gnu.org}
Free Software Evangelist oliva@{lsd.ic.unicamp.br, gnu.org}
-